mcp-troubleshoot

Warn

Audited by Snyk on Feb 26, 2026

Risk Level: MEDIUM
Full Analysis

MEDIUM W012: Unverifiable external dependency detected (runtime URL that controls agent).

  • Potentially malicious external URL detected (high risk: 0.80). The skill instructs running "npx @gongrzhe/server-gmail-autoauth-mcp auth", which causes npx to fetch and execute remote npm package code at runtime and is presented as the required re-authentication step for Gmail MCP (package: @gongrzhe/server-gmail-autoauth-mcp), so this external dependency executes remote code during runtime.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Feb 26, 2026, 10:19 PM